OpenSSL

OpenSSL

274 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 47.63%
  • Veröffentlicht 04.06.2009 16:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

ssl/s3_pkt.c in OpenSSL before 0.9.8i allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a DTLS ChangeCipherSpec packet that occurs before ClientHello.

  • EPSS 13.46%
  • Veröffentlicht 04.06.2009 16:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The dtls1_retrieve_buffered_fragment function in ssl/d1_both.c in OpenSSL before 1.0.0 Beta 2 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an out-of-sequence DTLS handshake message, related to a...

  • EPSS 2.88%
  • Veröffentlicht 19.05.2009 19:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The dtls1_buffer_record function in ssl/d1_pkt.c in OpenSSL 0.9.8k and earlier 0.9.8 versions allows remote attackers to cause a denial of service (memory consumption) via a large series of "future epoch" DTLS records that are buffered in a queue, ak...

Exploit
  • EPSS 13.25%
  • Veröffentlicht 19.05.2009 19:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Multiple memory leaks in the dtls1_process_out_of_seq_message function in ssl/d1_both.c in OpenSSL 0.9.8k and earlier 0.9.8 versions allow remote attackers to cause a denial of service (memory consumption) via DTLS records that (1) are duplicates or ...

Exploit
  • EPSS 8.56%
  • Veröffentlicht 19.05.2009 19:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Use-after-free vulnerability in the dtls1_retrieve_buffered_fragment function in ssl/d1_both.c in OpenSSL 1.0.0 Beta 2 allows remote attackers to cause a denial of service (openssl s_client crash) and possibly have unspecified other impact via a DTLS...

  • EPSS 2.73%
  • Veröffentlicht 27.03.2009 16:30:02
  • Zuletzt bearbeitet 09.04.2025 00:30:58

OpenSSL before 0.9.8k on WIN64 and certain other platforms does not properly handle a malformed ASN.1 structure, which allows remote attackers to cause a denial of service (invalid memory access and application crash) by placing this structure in the...

  • EPSS 2.42%
  • Veröffentlicht 27.03.2009 16:30:01
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The CMS_verify function in OpenSSL 0.9.8h through 0.9.8j, when CMS is enabled, does not properly handle errors associated with malformed signed attributes, which allows remote attackers to repudiate a signature that originally appeared to be valid bu...

  • EPSS 10.02%
  • Veröffentlicht 27.03.2009 16:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The ASN1_STRING_print_ex function in OpenSSL before 0.9.8k allows remote attackers to cause a denial of service (invalid memory access and application crash) via vectors that trigger printing of a (1) BMPString or (2) UniversalString with an invalid ...

Exploit
  • EPSS 0.26%
  • Veröffentlicht 20.02.2009 19:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

OpenSSL, probably 0.9.6, does not verify the Basic Constraints for an intermediate CA-signed certificate, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack, a related issue to CVE-2002-0970.

  • EPSS 0.24%
  • Veröffentlicht 07.01.2009 17:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

OpenSSL 0.9.8i and earlier does not properly check the return value from the EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys.